2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23292 | MEDIUM | 4.6 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta... |
| CVE-2025-56520 | MEDIUM | 5.3 | 0.6% | Sep 30, 2025 | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_... |
| CVE-2025-56207 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et... |
| CVE-2025-56676 | MEDIUM | 5.4 | 0.3% | Sep 30, 2025 | TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p... |
| CVE-2025-56018 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category... |
| CVE-2025-55797 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth... |
| CVE-2025-54477 | MEDIUM | 5.3 | 0.3% | Sep 30, 2025 | Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. |
| CVE-2025-54476 | MEDIUM | 4.8 | 0.3% | Sep 30, 2025 | Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class. |
| CVE-2025-57852 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas... |
| CVE-2025-28016 | MEDIUM | 4.8 | 0.2% | Sep 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re... |
| CVE-2025-9232 | MEDIUM | 5.9 | 2.0% | Sep 30, 2025 | Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p... |
| CVE-2025-9231 | MEDIUM | 6.5 | 2.2% | Sep 30, 2025 | Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ... |
| CVE-2025-52050 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr... |
| CVE-2025-52049 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ... |
| CVE-2025-52047 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj... |
| CVE-2025-52043 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac... |
| CVE-2025-10859 | MEDIUM | 4 | 0.1% | Sep 30, 2025 | Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info... |
| CVE-2025-10217 | MEDIUM | 6 | 0.3% | Sep 30, 2025 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat... |
| CVE-2025-9948 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-9946 | MEDIUM | 6.1 | 0.1% | Sep 30, 2025 | The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2025-9852 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-... |
| CVE-2025-8777 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver... |
| CVE-2025-8624 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in... |
| CVE-2025-8623 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm... |
| CVE-2025-8608 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now